Privacy policy (the app)
The short version
Nudge runs locally. Search, math, unit conversion, and system commands never leave your machine. Nudge uses the network only when you use a network feature, plus a small, infrequent licence and update check. The only things that ever go out over the network are the six calls listed below, and every one of them is either something you triggered (a purchase, a bug report you chose to send, a currency conversion you typed) or that licence/update check. Nothing you type is ever sent.
The exact network calls
| Call | Trigger | Sent | Received |
|---|---|---|---|
| Activation | You enter a licence key | Your licence key, a hashed machine fingerprint (below), the app version | An activation token, the server time, the email tied to your licence |
| Licence heartbeat | Automatic, every 7 days while the app runs | Your licence key, your stored activation token | Whether your licence is still active, the server time |
| Update check | Automatic, on the update schedule | Nothing: a plain, unauthenticated request for the current release manifest | The manifest, cryptographically signed, checked against a key built into the app before anything is trusted |
| Plugin registry check | Browsing or updating plugins | Nothing by default; if activated, your activation token, sent only to the registry address | The plugin catalog, signed the same way as the update manifest |
| Plugin / update downloads | Installing a plugin or accepting an update | Nothing beyond the download request itself | The plugin or installer file |
| Currency rates | You type a currency conversion, such as 12 usd to inr; at most once an hour. A network feature: on by default, off with the Network features switch (below) | Nothing about you; a plain request for the day’s exchange rates against USD, identical for every user | The day’s exchange rates |
What’s deliberately not on this list: your searches, the files you open, what you type into the launcher, and your clipboard history. None of it is sent anywhere, ever, by any of the calls above.
Your IP address: like any web request, each of the six calls above reveals your IP address at the network level (to Cloudflare for the first five, to ExchangeRate-API for currency rates). That’s how the internet works, not something Nudge adds. No application logic in Nudge attaches your IP to your licence record or your identity beyond routine, short-lived request logs used for abuse prevention.
Network features, and how to turn them off
A network feature is an answer in the launcher that needs the internet to work. Today there is one: currency conversion. It’s on by default, and its result row says the rates come from the internet, so you can see when it’s being used. Settings → Privacy → Network features turns every network feature off at once; with it off, Nudge doesn’t make the currency-rates call at all, and a currency conversion says it’s turned off instead of fetching rates. Any network feature added in a future version follows the same switch and is added to the table above before it ships.
The switch covers answers in the launcher. It doesn’t cover activation, the licence heartbeat, the update check, or plugin downloads, which are listed separately above.
Bug reports: different from all of the above
Reporting a bug (Settings → About → Report a bug) does not automatically send anything. It builds a report on your machine (app version, OS version, which plugins you have installed, name/version only, and a stack trace made only of code frames) and shows it to you in full before doing anything. The report is never allowed to contain your search queries or file paths. The report format itself has no field for them, not just a setting that could be turned on. Sending it means it’s copied for you to paste into a GitHub issue yourself; the app does not silently upload it.
What stays on your PC
Nudge never saves your keystrokes as you type. When you run a result, Nudge remembers that result on your PC so it can rank it higher next time and show it in Recents: the result’s title and subtitle, its icon, what it does (for example the file or app it opens, the text it copies, or the command it runs), how many times you’ve run it, and when you last did. For a calculation, that includes the expression you typed; for a web search you ran, the search term; for a > command, the command itself.
- Window switches are never remembered. A window’s title can be anything on screen (a document name, an email subject), so switching to a window doesn’t add it to Recents, and window entries saved by earlier versions are deleted the first time a new version starts.
- Web searches don’t appear in Recents.
- An audit log keeps a record of each
>command you run and each action you confirm that can’t be undone (such as ending a process), so you can see what was done. - Files and folders you open are kept in a short recent-paths list, used by features such as Quick Folders.
All of this lives under %AppData%\Nudge (and a cache of app icons under %LocalAppData%\Nudge) on your PC. None of it is sent anywhere, by any of the calls above. Settings → Privacy lets you turn history off and clear it; you can also delete everything at any time by removing those folders, and uninstalling Nudge offers to remove them for you. Screen recordings you make are saved to your Pictures folder, and are never uploaded either.
The machine fingerprint
Activation and the licence heartbeat identify your machine by a hash, not by your machine’s real hardware IDs. The hash is built from a few Windows identifiers plus a random value generated once when Nudge is installed, and only that hash ever leaves your machine. Think of it as a pseudonymous install ID: it lets us tell “the same install checking in again” from “a different install,” without transmitting anything that identifies your actual hardware to us or to anyone else.
Who processes this data (our processors)
- Cloudflare runs the activation/heartbeat/update/registry endpoints and stores licence records. No search or file data ever reaches it, because the app never sends any.
- ExchangeRate-API (open.er-api.com) is a third-party exchange-rate service that answers the currency-rates call. It’s an independent public service rather than a processor acting on our instructions, and it’s listed here so the list of who Nudge talks to is complete. It receives only a plain request for the day’s USD rates, the same request from every user, never the amount or currencies you typed (Nudge does that conversion on your machine). Like any web request, it sees your IP address. The rates are kept in memory for at most an hour and never saved to disk. If you’re offline, nothing is sent: Nudge says the conversion needs an internet connection instead.
- Our merchant of record processes your payment at checkout and is the seller of record for tax purposes. It receives your payment details and the email you buy with; it does not receive anything from the app itself. (The exact company is still being finalised, and this page is updated with its name before launch.)
None of them receives your searches, files, or clipboard contents, because the app never transmits them.
How long we keep it
Licence and activation records are kept for as long as your licence is active, plus a limited period afterward for fraud prevention and support (for example, so a refund or a support request about a past purchase can still be resolved). If you ask us to delete your data, we deactivate your licence and remove what identifies you beyond what we’re required to keep for accounting or legal reasons.
How we protect it
The activation/heartbeat/update/registry endpoints are designed to run over standard encrypted web connections (HTTPS). That’s the intent behind how they’re built, not yet something a live, deployed, independently-tested backend has confirmed, since Phase 9.6’s backend hasn’t been deployed as of this writing. Your licence key and machine fingerprint are never stored in plain text alongside your email in a way that lets one be read from the other without the licence system itself. We don’t ask for or store a password: there’s no account, so there’s nothing to phish or credential-stuff.
If you’re in India (the Digital Personal Data Protection Act, 2023)
We act as a Data Fiduciary under India’s DPDP Act, 2023 for the personal data described in this policy (your email, licence key, and the pseudonymous install ID). In plain terms:
- We only use your data for the purposes stated in this policy: issuing and validating your licence, and preventing fraud.
- By purchasing and activating a licence, you consent to that processing. You can withdraw consent at any time by asking us to delete your data (below). Doing so deactivates your licence, since we can no longer validate it without this data.
- You (as a Data Principal) have the right to access what we hold about you, correct it, have it erased, and raise a grievance if you think we’ve handled it wrong. You can also nominate another person to exercise these rights on your behalf if you’re unable to (for example, in the event of your death or incapacity).
- Our processors (Cloudflare and our merchant of record, above) may process your data outside India (ExchangeRate-API, above, is also outside India and sees only your IP address) as part of their normal global infrastructure. Section 16 of the DPDP Act permits this except to a country the Indian government specifically notifies as restricted. As of this policy’s last update, the government hadn’t notified any restricted country, so this doesn’t currently limit anything, but it’s a list that can change and is worth re-checking before launch.
- To raise a grievance or exercise any of the rights above, email the address at the bottom of this page. We aim to acknowledge it within a few days and resolve it well within whatever limit the DPDP Rules, 2025 set (some compliance guides cite a 90-day outer limit; we haven’t independently confirmed that figure against the Rules’ own text, so treat it as indicative, not guaranteed, until confirmed by counsel).
If you’re in the EU, UK, or somewhere with similar rules
Our basis for processing your data is performing the contract you bought (the licence) and our legitimate interest in preventing fraud and keeping the service running. You have the usual rights that come with that: to ask what we hold, to correct it, to have it deleted, and to complain to your local data protection authority if you think we’ve got something wrong. Start with the email below; most requests are simpler to just resolve directly.
What we don’t do
- No account required to use Nudge.
- No analytics or usage tracking beyond the calls listed above.
- No selling or renting any data to anyone.
- No cross-device tracking beyond the licence system recognising the same pseudonymous install ID checking in again.
Your choices
Email hello@nudgelauncher.com to ask what’s on file for your licence, or to have it deleted (this deactivates the licence).
- Turn off every network feature with Settings → Privacy → Network features (currency conversion is the only one today).
- Uninstalling Nudge stops all of the calls above; nothing continues to run in the background afterward. The uninstaller asks whether to also remove what Nudge kept on your PC (above); it keeps it unless you say yes.
Changes to this policy
If the network calls this policy describes change in a future version, this page is updated before that version ships, and the “last updated” date changes with it.